CVE-2022-48197
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
Record summary
CVE-2022-48197 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Description
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBYahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)ExploitDB exploitby SITE TeamNot analyzed1 file
Repository PoCs
GitHubryan412/CVE-2022-48197Repository PoCby ryan412Stars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMYahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site ScriptingCVSS 6.1
Reflected cross-site scripting (XSS) exists in the TreeView of YUI2 through 2800: up.php sam.php renderhidden.php removechildren.php removeall.php readd.php overflow.php newnode2.php newnode.php.
Impact
Attackers can inject malicious JavaScript through crafted mode parameters in multiple TreeView PHP files, potentially stealing user session tokens and performing actions on behalf of victims when they access the compromised pages.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery